
CVE-2026-27129: Craft CMS SSRF: The IPv6 Ghost in the Machine A sophisticated Server-Side Request Forgery (SSRF) bypass in Craft CMS leverages the often-overlooked disparity between legacy PHP networking functions and modern dual-stack infrastructure.... https://cvereports.com/reports/CVE-2026-27129
Post summary
The report discloses a Server‑Side Request Forgery bypass in Craft CMS that exploits differences between legacy PHP networking functions and modern dual‑stack IPv6 infrastructure.


